Premium Only Content
![Linked List Exploit Continued - GOT Overwrite - "Links 2+3" Pwn Challenge [ImaginaryCTF]](https://1a-1791.com/video/s8/1/V/Z/T/A/VZTAh.qR4e-small-Linked-List-Exploit-Continu.jpg)
Linked List Exploit Continued - GOT Overwrite - "Links 2+3" Pwn Challenge [ImaginaryCTF]
"Links 2" (Pwn) challenge from ImaginaryCTF (iCTF) 27/06/22 - "It turns out that there was a bug in how I was handling writing some elements, so I've fixed that. Also, I've stopped putting the flag in a global variable, because that's probably not a good idea. Double check my implementation one more time for me?". In this challenge we'll use Ghidra, GDB-PwnDbg and PwnTools to exploit a vulnerable custom LinkedList implementation by overwriting an global offset table GOT entry to point system(), so we can get a shell.
"Links 3" (Pwn) challenge from ImaginaryCTF (iCTF) 30/06/22 - "And now you guys are exploiting my View Time feature that I put there solely for your convenience? Fine, then - no more time for you!". This challenge has no view_time() function, so we lose the system() call. However, we can leak an arbitrary function from the GOT and use the Lib-C database to find the correct offsets (ret2libc). Hope you enjoy 🙂 #CTF #iCTF #ImaginaryCTF #Pwn #BinaryExploitation
Write-ups: https://github.com/Crypto-Cat/CTF/tree/main/ctf_events/ictf/pwn/links
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢ImaginaryCTF↣
https://imaginaryctf.org
https://twitter.com/imaginaryctf
https://discord.gg/9r8AJQkfs3
↢Video-Specific Resources↣
https://libc.blukat.me
https://libc.rip
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Links 1 Recap: 0:30
Reviewing Heap Layout in GDB-PwnDbg: 3:25
Keeping the Heap intact: 7:45
Links 2 Attack Plan: 11:55
Overwriting the GOT: 16:48
Stack Alignment: 20:08
Solution (leak system): 23:27
Links 3 (leak another lib-c function): 28:08
Recap: 33:27
End: 34:29
-
3:04:51
Due Dissidence
6 hours agoZelensky RETURNS To DC, HUGE Protests In Israel, Gal Gadot Blames Palestine For Flop, MSNBC Rebrands
31.4K14 -
1:19:29
The HotSeat
2 hours ago🚨 Dems Swear Mail-In Voting Is “Secure”… Trump Says HELL NO 🚨
14.2K7 -
LIVE
Reidboyy
9 hours ago $0.71 earnedNEW FREE FPS OUT ON CONSOLE TODAY! (Delta Force = BF6 Jr.)
66 watching -
29:20
Stephen Gardner
2 hours ago🔥YES! Trump unleashes Democrats’ worst nightmare!
16.9K7 -
LIVE
The Nunn Report - w/ Dan Nunn
2 hours ago[Ep 731] Trump Leading the World | Islam NOT Compatible with West | Guest Sam Anthony [your[NEWS
144 watching -
2:05:30
Side Scrollers Podcast
6 hours agoEveryone Hates MrBeast + FBI Spends $140k on Pokemon + All Todays News | Side Scrollers Live
84.9K4 -
46:56
The White House
6 hours agoPress Secretary Karoline Leavitt Briefs Members of the Media, Aug. 19, 2025
51K67 -
1:11:36
Sean Unpaved
5 hours agoFootball Flashpoint: Bengals' D in Distress, Colts' Bet on Jones, & Micah's Trade Talks
39.1K2 -
DVR
The Robert Scott Bell Show
2 hours agoVaccine Lawsuits & Legal Fights, Autism–ADHD Link to Tylenol, MAHA Action, Caitlin Sinclair, Fat Jabs for Pets - The RSB Show 8-19-25
9.19K1 -
2:57:22
Right Side Broadcasting Network
9 hours agoLIVE REPLAY: White House Press Secretary Karoline Leavitt Holds a Press Briefing - 8/19/25
95.1K47